Missing Authorization Vulnerability in Kibana by Elastic
CVE-2026-72664
6.5MEDIUM
What is CVE-2026-72664?
A missing authorization vulnerability in Kibana allows users with limited permissions to execute Elastic Defend response actions on managed hosts. Specifically, users authorized only for detection rule creation can improperly link automated response actions to these rules without possessing the required endpoint response action privileges. As a result, when alerts are triggered, these unauthorized response actions can be executed against the affected hosts, posing significant security risks.
Affected Version(s)
Kibana 8.9.0 <= 8.19.19
Kibana 9.0.0 <= 9.4.4